State Notifications differ around these 4 elements
is there a private right of action under CCPA, Amended CPRA?
yes, 2 situations
CA enforcement action against Sephora
30 day cure in CPRA?
CPRA removes the 30 day cure and gives CPPA discretionary power and time to cure a violation.
CPRA; Is written notice require prior to a consumer initiating an action for pecuniary damages suffered as a result?
no
what about third parties and the Colorado, Concerning Strengthening protections for consumer data privacy law.
What policy is called out in the Colorado law?
entities must write a records destruction policy for those records containing PII
What should be addressed in the comprehensive security program under Massachusetts Standards for the Protection of Personal Information? (7)
what should be addressed under NY Shield Act 2019?
Who enforces NY Shield Act?
NY AG
under NY-CRR 2017, when should a security breach be reported?
within 72 hours
Who is exempt from NY-CRR?
What is special about Ohio Data Protection Act?
sets up incentive, safe harbor if businesses follow certain frameworks (NIST CSF, 800-171, ISO 27000, GLBA, HIPA, FISMA)
what two states require insurers to submit annual compliance certifications to the state?
New York and south Carolina
Does Virginia CDPA include employee data?
No
What is the scope of V CDPA?
what are the 6 consumer rights under the V CDPA?
The CDPA fails to provide any exceptions to these rights